Description

A flapping IPsec VPN tunnel is a tunnel that repeatedly goes up and down or continuously re-establishes its security associations. This behavior can affect both site-to-site VPNs and remote IPsec VPNs and may lead to intermittent service disruption.


Symptoms

Customers may observe intermittent connectivity, brief traffic interruptions, or repeated tunnel recovery events. In system logs, this can appear as recurring VPN up/down alarms or repeated IPsec SA establishment messages.

Solution

To troubleshoot a flapping VPN tunnel, Juniper recommends the following high-level checks:


Review system logs to confirm whether the issue is isolated to a single VPN and to identify repeated up/down or rekey events.


Verify VPN monitoring settings, including Dead Peer Detection (DPD) and any tunnel monitoring features, since aggressive or mismatched monitoring behavior can contribute to tunnel instability.


Confirm that both VPN peers use matching IKE/IPsec settings, including proposals, lifetimes, authentication settings, and traffic selectors or proxy identities. Mismatches can cause the tunnel to drop or flap, especially during rekey events.


If the issue continues after configuration review, collect relevant VPN logs and trace information, and contact Juniper Support for deeper analysis.


This article is intended as general guidance only and does not include any environment-specific or customer-specific data. For detailed diagnostic steps and platform-specific behavior, refer to Juniper’s official troubleshooting documentation.

Modification History

2026-06-17 : Article Created